← Späť na vyhľadávanie CVE

CVE-2026-49864

wetty

Popis

wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download escape sequence and interpolates it raw into a Toastify HTML string (`escapeMarkup: false`). Any output the victim renders - a `cat`-d file, a tailed log, an SSH MOTD, a `curl` response - that contains `\x1b[5i...:...\x1b[4i` runs script in the wetty origin and types attacker-chosen keystrokes into the victim-s SSH session. Version 3.0.4 fixes the issue.

CVSS 8.6EPSS 0.33%Riziko 0.89
Zobraziť zdroj
Zverejnené
2026-08-13 20:17:22
Dotknuté verzie
<3.0.4
Typ
Knižnica
Posledná úprava
2026-08-18 02:17:27
Vektor
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X